GSLC · Question #63
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network…
The correct answer is B. Containment. In the standard incident handling lifecycle, Containment immediately follows Identification to limit the damage and prevent the incident from spreading.
Question
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?
Options
- ARecovery
- BContainment
- CPreparation
- DIdentification
How the community answered
(30 responses)- A3% (1)
- B87% (26)
- C3% (1)
- D7% (2)
Why each option
In the standard incident handling lifecycle, Containment immediately follows Identification to limit the damage and prevent the incident from spreading.
Recovery is a later phase that restores systems to normal operation after the threat has been eradicated - it cannot occur before Containment and Eradication.
After identifying a DoS attack (Identification phase), the next step in the incident handling process is Containment, which involves isolating affected systems, blocking malicious traffic, or segmenting the network to prevent the attack from spreading further to other internal systems.
Preparation is the first phase of incident handling where policies, tools, and procedures are established before any incident occurs - it is not a response action taken after identification.
Identification is the phase that was just completed when the DoS attack was recognized - repeating it is not the correct next step in the process.
Concept tested: Incident handling lifecycle phases order
Source: https://www.nist.gov/publications/computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.